ThinkPatternGet the app
Perspective
TECHNOLOGY · SEP 14, 2026

The new defenses against AI persuasion, and whom they protect

A year after NATO named "cognitive warfare" a strategic threat, China answered with the world's only full defense and pointed it inward, at its own people; the United States answered by erasing the word "misinformation" from its safety guidelines, and nothing followed.

In August 2025, NATO's Strategic Warfare Development Command put a formal definition on paper. Artificial intelligence and social media, it said, could now deliver "cognitive payloads," material designed to erode a target country's norms and values by working directly on its population's thinking, and this "cognitive warfare" was henceforth a strategic national-security threat. The oddest part of the document was the prescription. The recommended defense was not a filter, a label, or a statute. It was character development and critical thinking, cultivated in ordinary citizens [1]. The threat itself, at least, is not speculative. Peer-reviewed studies run across four countries have measured how much a chatbot arguing politics moves voters: roughly four times more effectively than television advertising, with the shift still detectable a month later in 36 to 42 percent of British subjects. The most persuasive bots were not the most accurate ones. They were the most prolific, flooding the conversation with evidence-sounding argument without regard to whether any of it was true [2]. Thirteen months after the alliance named that threat, the record of what governments actually built against it is complete enough to lay side by side, and it sits at two ends. China built first, in dated installments, each one tighter than the last.

2025-09 Mandatory labeling of all AI-generated content takes effect: a visible tag, a hidden watermark, and a unique ID traceable to the origin of every item [3]

2026-04 Draft rules for synthetic "digital humans" require prominent labels and ban outright any content that threatens national security, promotes secession, or incites subversion of state power [4]

2026-09 Content companies must register with the state, verify the real identity of every creator, and take legal responsibility for censoring their own platforms, on pain of fines up to 200,000 yuan and account shutdowns [5]

The first installment came with an instruction from the Cyberspace Administration of China to the platforms that would enforce it [3].

implement robust AI content monitoring, enforce mandatory labeling and apply penalties to anyone who disseminates misinformation through AI or uses the technology to manipulate public opinion. — Cyberspace Administration of China

That language does not face the authors of foreign payloads. It faces anyone on a Chinese platform whose output might be judged to manipulate public opinion, with the state keeping the definition. Eight days after the last installment took effect, on Monday, State Security Minister Chen Yixin said in public what the entire construction defends [6].

directly threaten China's political security, institutional security and ideological security — Chen Yixin

None of those three words describes the public's safety. All three describe the state's. Chen warned of hostile forces using AI for public-opinion wars, to spread political rumors and incite social division [6], and the September rules arrived ready to police exactly the kind of reporting critics say will now become too risky: on unemployment, on wages that went unpaid, on housing projects standing unfinished [5]. Of all the countries that heard NATO's warning, China took it most literally. It built the only complete defense on Earth, and it points inward, at the cognition of its own people. Washington's thirteen months divide into a subtraction and a string of hits. The subtraction came early: the administration's AI Action Plan had the National Institute of Standards and Technology strip the references to misinformation from its AI-safety guidelines, the one federal document that had addressed what models say, not just what they can do [7]. There is no federal labeling law. Then the demonstrations. In the summer of 2025, an unknown actor used an AI voice clone of Secretary of State Marco Rubio, plus generated text, to reach at least three foreign ministers, a governor, and a member of Congress; the government's advice afterward was better detection tools and hardware security keys to protect officials' identities [8]. In the first week of that September, Special Operations Command went shopping for AI systems to automate influence campaigns overseas: multiple chatbots running with minimal human oversight, controlling narratives in real time and suppressing dissenting voices in foreign audiences [9]. This March, the National Republican Senatorial Committee aired an AI deepfake of Texas Democratic Senate candidate James Talarico, and it was lawful, because Texas bans faked campaign media only within 30 days of an election and the committee ran its ad outside the window. Senator Andy Kim of New Jersey called for a federal law to close that gap. None exists [10]. Later the same month, during the Iran conflict, the Revolutionary Guard fielded at least 62 covert accounts posing as Westerners to push AI-generated material against the American president, boosted by Russian and Chinese amplification networks. The White House's public response was to go after the coverage [11].

Why is NPR writing puff pieces about Iran's social media strategy? — Anna Kelly

In April, an Ohio Senate candidate mailed voters an AI-doctored photograph showing his opponent posing with drag queens [12]. The sequence needs no theory behind it. When the target was the secretary of state's voice, Washington answered with hardware. When the target was the electorate, it answered with a press complaint. Outside the two poles, the remaining defenses grade quickly, because the criteria are simple: what does it bind, and whom does it cover. India's Election Commission wrote the strongest one last October, invoking constitutional powers: AI-generated campaign material must carry a label spanning at least a tenth of its surface, must name the entity responsible, and misleading synthetic content must come down within three hours. That binds every campaign in the world's largest democracy, the only complete electoral defense any democracy has fielded, and it binds no one outside an Indian election [13]. Meta, in February, bound its own surfaces for the midterms: mandatory AI disclosure on political ads, detection systems to label synthetic material, and a block on new political ads in the final week. That binds advertisers on Facebook and Instagram, for exactly as long as Meta chooses to be bound [14]. The technical layer is volunteer work: Google and OpenAI wired SynthID watermarks and C2PA content credentials into Search, Chrome, and Android in May, with Nvidia, ElevenLabs, and Kakao signing on [15]. A voluntary watermark binds only what volunteers to carry it, and in August a developer named Guillaume Meyer released Watermarks Remover, a free open-source tool that strips invisible AI watermarks by disturbing their statistical fingerprints. It drew more than two million impressions on X. Meyer has described his own creation with unusual candor [16].

Anthropic's version of AI watermarks generates more problems than they solve — Guillaume Meyer

Which returns that first document to the table. Its odd prescription turns out to be the one entry on the defense map that no one got wrong, because no one built it. No ministry was ever tasked with raising the critical thinking of the public now being worked on at four times television strength, at volume, true or not. In China the state took the assignment and redirected it at the population. In India an election commission took it for campaign season. In America the assignment sits where the alliance left it, with the citizen. The censors got a ministry. The campaigns got a commission. The platforms got policies, the watermarks got a remover, and the voters got the original advice, unimproved since the day it was written. The machines, by now, are measured. The advice is not.


Sources
  1. 1. NATO Defines Cognitive Warfare as Strategic National Security Threat
  2. 2. AI Chatbots Sway Voters More Effectively Than Political Ads
  3. 3. China Mandates Labeling for All AI Generated Content
  4. 4. China Proposes Regulations to Oversee Digital Humans
  5. 5. China Implements New Social Media Content Regulations
  6. 6. China Rejects U.S. Calls to Slow AI Development
  7. 7. Trump Releases AI Action Plan Amid Federal Research Cuts
  8. 8. State Department Investigates AI Impersonation of Marco Rubio
  9. 9. US Special Operations Command Seeks AI to Automate Influence Campaigns
  10. 10. NRSC Releases AI Deepfake Ad Targeting Texas Senate Candidate
  11. 11. Iran Deploys AI Disinformation Campaign Targeting Trump and Netanyahu
  12. 12. Ohio Senate Candidate Uses AI Mailer to Target Opponent
  13. 13. Election Commission of India Mandates Labeling of AI Campaign Content
  14. 14. Meta Announces Election Integrity Policies for 2026 Midterms
  15. 15. Google LLC and OpenAI Inc. Adopt SynthID Watermarking for AI Content
  16. 16. Guillaume Meyer Releases Tool to Strip AI Watermarks

Keep reading in the app

The full perspective, free in the app.

Download on the App StoreComing soonGoogle Play